You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring XML配置:如何将静态final RequestMatcher作为Bean构造器参数?

Spring Security 5.2.15 配置CSRF并注入DEFAULT_CSRF_MATCHER的正确方式

问题原因分析

你遇到的两个错误本质是配置语法不符合Spring XML Schema规范和AndRequestMatcher的构造方法要求:

  • 找不到AndRequestMatcher构造方法:AndRequestMatcher在5.2.x版本中核心构造方法接收List<RequestMatcher>类型参数,直接传递单个/多个独立的RequestMatcher实例会匹配不到对应构造方法。
  • b:value属性错误:XML中<value>标签本身不需要额外的value属性,错误写法(如<b:value value="xxx"/>)违反了Schema约束。

解决方案

根据你的需求(给特定URL禁用CSRF,同时注入CsrfFilter.DEFAULT_CSRF_MATCHER),以下是两种可行的配置方式:

1. XML配置方式

需引入util命名空间来引用静态常量,同时正确构造AndRequestMatcher的参数列表:

<beans xmlns="http://www.springframework.org/schema/beans"
       xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
       xmlns:sec="http://www.springframework.org/schema/security"
       xmlns:util="http://www.springframework.org/schema/util"
       xsi:schemaLocation="
           http://www.springframework.org/schema/beans
           http://www.springframework.org/schema/beans/spring-beans.xsd
           http://www.springframework.org/schema/security
           http://www.springframework.org/schema/security/spring-security.xsd
           http://www.springframework.org/schema/util
           http://www.springframework.org/schema/util/spring-util.xsd">

    <!-- 定义需要排除CSRF校验的URL匹配器 -->
    <bean id="excludedCsrfUrls" class="org.springframework.security.web.util.matcher.AntPathRequestMatcher">
        <constructor-arg value="/api/**"/> <!-- 替换为你的目标URL -->
    </bean>

    <!-- 构造自定义CSRF匹配器:默认规则 + 排除指定URL -->
    <bean id="csrfMatcher" class="org.springframework.security.web.util.matcher.AndRequestMatcher">
        <constructor-arg>
            <list>
                <!-- 注入静态常量DEFAULT_CSRF_MATCHER -->
                <util:constant static-field="org.springframework.security.web.csrf.CsrfFilter.DEFAULT_CSRF_MATCHER"/>
                <!-- 通过NegatedRequestMatcher排除指定URL -->
                <bean class="org.springframework.security.web.util.matcher.NegatedRequestMatcher">
                    <constructor-arg ref="excludedCsrfUrls"/>
                </bean>
            </list>
        </constructor-arg>
    </bean>

    <!-- 在Spring Security核心配置中使用自定义匹配器 -->
    <sec:http>
        <!-- 其他安全配置(如授权、登录等) -->
        <sec:csrf matcher-ref="csrfMatcher"/>
    </sec:http>
</beans>

2. Java配置方式(推荐)

如果项目支持JavaConfig,这种方式更简洁且不易出错:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.security.web.csrf.CsrfFilter;
import org.springframework.security.web.util.matcher.AndRequestMatcher;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;
import org.springframework.security.web.util.matcher.NegatedRequestMatcher;
import org.springframework.security.web.util.matcher.RequestMatcher;

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    // 构造自定义CSRF匹配器Bean
    @Bean
    public RequestMatcher csrfMatcher() {
        // 定义需要排除的URL规则
        RequestMatcher excludedUrls = new AntPathRequestMatcher("/api/**");
        // 组合默认CSRF匹配规则和排除逻辑
        return new AndRequestMatcher(
                CsrfFilter.DEFAULT_CSRF_MATCHER,
                new NegatedRequestMatcher(excludedUrls)
        );
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
                // 其他安全配置(如.authorizeRequests()等)
                .csrf(csrfConfig -> csrfConfig
                        .requireCsrfProtectionMatcher(csrfMatcher())
                );
    }
}

内容的提问来源于stack exchange,提问作者Myy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 03:20:26